Vulnerability Description
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Cryptpad | < 2025.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/cryptpad/cryptpad/blob/15c81aa8ccb737a9a1167481f4a699af331364Product
- https://github.com/cryptpad/cryptpad/commit/d5e4830ba104a4a442cb23aab5378b8565a9Patch
- https://github.com/cryptpad/cryptpad/security/advisories/GHSA-vq9h-x3gr-v8rjExploitVendor Advisory
FAQ
What is CVE-2025-49590?
CVE-2025-49590 is a vulnerability with a CVSS score of 6.1 (MEDIUM). CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. T...
How severe is CVE-2025-49590?
CVE-2025-49590 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-49590?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Cryptpad.